AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-9015

MEDIUM · CVSS 6.8 EPSS 2.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-11-24 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable.

CVE
CVE-2014-9015
Severity
MEDIUM
CVSS
6.8
EPSS
2.46%

Original NVD Description

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.